CVE-2015-5400: Debian Linux

Medium severity, CVSS 6.8. EPSS: 20.8% chance of exploitation in the next 30 days.

Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.

Affected products

Published 2015-09-28. Last modified 2026-06-17.